Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

79,230cataloged exploits
36,424CVEs with public exploitation
24,695lab-tested
5,629 exploits
ReferênciaVexDay Proof
Netartmedia Blog System - SQL Injection
CVE-2008-5311webappsphp
SQL injection vulnerability in image.php in NetArt Media Blog System 1.5 allows remote attackers to execute arbitrary SQ
23RISK
open
ReferênciaVexDay Proof
SFS EZ Career - SQL Injection
CVE-2008-6867webappsphp
SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbit
23RISK
open
ReferênciaVexDay Proof
Autodealers CMS AutOnline - 'id' SQL Injection
CVE-2008-4074webappsphp
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary
23RISK
open
ReferênciaVexDay Proof
LocazoList 2.01a beta5 - 'subcatID' SQL Injection
CVE-2007-0129webappsasp
SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitra
23RISK
open
ReferênciaVexDay Proof
ThWboard 3.0b2.84-php5 - SQL Injection / Code Execution
CVE-2007-0340webappsphp
SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execu
23RISK
open
ReferênciaVexDay Proof
WebPortal CMS 0.7.4 - 'download.php' SQL Injection
CVE-2008-4345webappsphp
SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitr
23RISK
open
ReferênciaVexDay Proof
LightRO CMS 1.0 - 'index.php?projectid' SQL Injection
CVE-2007-0904webappsphp
SQL injection vulnerability in projects.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Injader CMS 2.1.1 - 'id' SQL Injection
CVE-2008-5890webappsphp
SQL injection vulnerability in feeds.php in Injader before 2.1.2 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
XOOPS Module debaser 0.92 - 'genre.php' Blind SQL Injection
CVE-2007-1805webappsphp
SQL injection vulnerability in genre.php in the debaser 0.92 and earlier module for Xoops allows remote attackers to exe
23RISK
open
ReferênciaVexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
CVE-2008-6881webappsphp
Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Phil-a-Form 1.2.0.0 - SQL Injection
CVE-2007-2933webappsphp
SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! al
23RISK
open
ReferênciaVexDay Proof
PNPHPBB2 < 1.2i - 'viewforum.php' SQL Injection
CVE-2007-3584webappsphp
SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execut
23RISK
open
ReferênciaVexDay Proof
Prozilla Directory Script - 'Directory.php?cat_id' SQL Injection
CVE-2007-3809webappsphp
Multiple SQL injection vulnerabilities in Prozilla Directory Script allow remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Mambo Component Remository - 'cat' SQL Injection
CVE-2007-4505webappsphp
SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers
23RISK
open
ReferênciaVexDay Proof
Active Force Matrix 2 - Authentication Bypass
CVE-2008-5634webappsasp
SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Vortex Portal 1.0.42 - Remote File Inclusion
CVE-2007-5842webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vortex Portal 1.0.42 allow remote attackers to execute arbitrary P
35RISK
open
ReferênciaVexDay Proof
Ktools Photostore 3.5.1 - 'gid' SQL Injection
CVE-2008-6647webappsphp
SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL c
23RISK
open
ReferênciaVexDay Proof
Tiger Dms - Authentication Bypass
CVE-2009-1503webappsphp
Multiple SQL injection vulnerabilities in login.php in Tiger Document Management System (DMS) allow remote attackers to
23RISK
open
ReferênciaVexDay Proof
MaxCMS 2.0 - 'm_username' Arbitrary Create Admin
CVE-2009-1818webappsphp
SQL injection vulnerability in admin/admin_manager.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL co
23RISK
open
ReferênciaVexDay Proof
Joomla! Component Bible Study 1.5.0 - 'id' SQL Injection
CVE-2008-2643webappsphp
SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attack
23RISK
open
ReferênciaVexDay Proof
Mybizz-Classifieds - 'cat' SQL Injection
CVE-2008-2845webappsphp
SQL injection vulnerability in index.php in MyBizz-Classifieds allows remote attackers to execute arbitrary SQL commands
23RISK
open
ReferênciaVexDay Proof
Webdevindo-CMS 0.1 - 'hal' SQL Injection
CVE-2008-2875webappsphp
SQL injection vulnerability in index.php in Webdevindo-CMS 1.0.0 allows remote attackers to execute arbitrary SQL comman
23RISK
open
ReferênciaVexDay Proof
geccBBlite 2.0 - 'id' SQL Injection
CVE-2008-4517webappsphp
SQL injection vulnerability in leggi.php in geccBBlite 2.0 allows remote attackers to execute arbitrary SQL commands via
23RISK
open
ReferênciaVexDay Proof
myEvent 1.6 - 'eventdate' SQL Injection
CVE-2008-4650webappsphp
SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Aj RSS Reader - 'url' SQL Injection
CVE-2008-4753webappsphp
SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL comm
23RISK
open
ReferênciaVexDay Proof
Mambo Component mambads 1.0 RC1 Beta - SQL Injection
CVE-2008-5226webappsphp
SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote atta
23RISK
open
ReferênciaVexDay Proof
SHOP-INET 4 - 'grid' SQL Injection
CVE-2009-0292webappsphp
SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands vi
23RISK
open
ReferênciaVexDay Proof
Script Toko Online 5.01 - SQL Injection
CVE-2009-0296webappsphp
SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute a
23RISK
open
ReferênciaVexDay Proof
Joomla! Component com_waticketsystem - Blind SQL Injection
CVE-2009-0333webappsphp
SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote
23RISK
open
ReferênciaVexDay Proof
Joomla! Component astatsPRO 1.0 - 'refer.php' SQL Injection
CVE-2008-0839webappsphp
SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attack
23RISK
open
previouspage 167 / 188next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.